All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Extra-Territorial Application of the IT Act: Sections 1(2) and 75

Cybercrime ignores borders. A server in India can be attacked from a laptop in another continent in seconds, and the attacker may never set foot in India. A cyber law confined to acts done within India would be almost useless. The IT Act therefore reaches beyond India's territory, but only on a defined condition: the act must involve a computer, computer system or computer network located in India. This note explains the statutory provisions, the principles of international jurisdiction behind them, how they compare with other Indian laws, and how the law is actually enforced against persons abroad.

1. The Stone across the Border

A man standing across the border throws a stone that breaks a window in an Indian village. He never entered India, yet the harm happened here, and every legal system accepts that India may punish him if it can get hold of him. A cyber attack is the same stone, thrown through a network. Section 75 says that if the stone lands on a computer in India, Indian law applies to the thrower, whoever and wherever he is.

2. The Statutory Provisions

Sections 1(2) and 75, Information Technology Act, 2000

Section 1(2). It shall extend to the whole of India and, save as otherwise provided in this Act, it applies also to any offence or contravention thereunder committed outside India by any person.

Section 75. Act to apply for offence or contravention committed outside India. (1) Subject to the provisions of sub-section (2), the provisions of this Act shall apply also to any offence or contravention committed outside India by any person irrespective of his nationality. (2) For the purposes of sub-section (1), this Act shall apply to an offence or contravention committed outside India by any person if the act or conduct constituting the offence or contravention involves a computer, computer system or computer network located in India.

  • Two conditions. The act must be an offence or contravention under the Act, and the act or conduct must involve a computer, computer system or computer network located in India.
  • Any person. Nationality is irrelevant. A foreign national acting from abroad is covered, and so is an Indian national.
  • Offences and contraventions. The reach extends to civil contraventions under Chapter IX as well as offences under Chapter XI, so a person abroad may face a claim for compensation before an adjudicating officer.
  • 'Save as otherwise provided'. Section 1(2) states the general extension; Section 75(2) supplies the limiting condition. The two are read together.
  • 'Involves'. A wide word: the Indian computer may be the target, the tool, or the place where data is stored or damage is caused.

Does the IT Act reach the act?

Figure 1: Does the IT Act reach the act?

3. Principles of Jurisdiction

The bases on which a State claims jurisdiction

Figure 2: The bases on which a State claims jurisdiction

  • Basis of Section 75. Section 75 rests mainly on the objective territorial or effects principle: the act is done abroad, but its target or effect is a computer in India. Because it applies irrespective of nationality, it does not depend on the nationality principle.
  • Protective element. Where the attack is on critical information infrastructure or amounts to cyber terrorism under Section 66F, the protective principle also supports jurisdiction.
  • Limit. The Act does not claim universal jurisdiction. An attack from abroad on a foreign computer, with no Indian computer involved, is outside Section 75 even if the attacker is Indian.

⚠ Exam trap

Do not write that the IT Act follows the offender wherever he goes. Section 75 is tied to the location of the computer, not the person. An Indian citizen who hacks a bank server in New York, with no Indian computer involved, is outside Section 75, though he may still be liable under the BNS for BNS offences committed abroad (s.1(5)(a) BNS).

4. Comparison with Other Indian Laws

Extra-territorial hooks across Indian law

Figure 3: Extra-territorial hooks across Indian law

  • BNS, s.1(5)(c). The BNS applies to any person in any place beyond India committing an offence targeting a computer resource located in India. This clause was first added to Section 4 of the IPC by the IT (Amendment) Act, 2008, so BNS offences such as cheating or extortion committed through an attack on an Indian computer are also reachable.
  • BNS, s.1(4). A person liable under any law in force in India to be tried for an offence committed beyond India is dealt with under the BNS as if the act had been committed within India.
  • DPDP Act, s.3(b). Applies to processing of digital personal data outside India if it is in connection with offering goods or services to Data Principals within India, an example of the effects or targeting approach.
  • IT Rules, 2021. Due diligence duties bind intermediaries that serve users in India, including foreign platforms, which must appoint officers resident in India if they are significant social media intermediaries.

5. Procedure: Inquiry and Trial in India

  • Section 208 BNSS (formerly s.188 CrPC). An offence committed outside India by a citizen of India, or by a person on an Indian ship or aircraft, may be dealt with as if committed at any place in India where the offender is found. No such offence may be inquired into or tried in India without the previous sanction of the Central Government.
  • Thota Venkateswarlu v. State of A.P., (2011) 9 SCC 527. Previous sanction under Section 188 CrPC is needed only for offences committed outside India; offences committed within India, even as part of the same transaction, can proceed without it.
  • Place of trial. Where the act is done abroad but its consequence ensues in India, as when an Indian server is damaged, the court within whose jurisdiction the consequence ensued may try it (s.199 BNSS, formerly s.179 CrPC)
  • Evidence from abroad. A court may issue a letter of request to a court or authority abroad for examination of witnesses or production of documents (s.112 BNSS, formerly s.166A CrPC). Copies of depositions or exhibits taken abroad before a judicial officer or an Indian diplomatic or consular representative may be received in evidence (s.209 BNSS, formerly s.189 CrPC)

6. Enforcement Abroad

Tools for reaching persons and data outside India

Figure 4: Tools for reaching persons and data outside India

  • Mutual legal assistance. India relies on bilateral mutual legal assistance treaties and letters rogatory to obtain data held abroad, which is often slow.
  • Extradition. An offender abroad can be brought to India only under the Extradition Act, 1962 and a treaty or arrangement, usually subject to double criminality.
  • International instruments. India is not a party to the Council of Europe's Budapest Convention on Cybercrime, 2001. The UN General Assembly adopted a Convention against Cybercrime in December 2024.
  • Platforms and data in India. Practical enforcement increasingly works through duties on platforms serving Indian users (Rules 3 and 4 of the 2021 Rules), CERT-In's requirement to keep logs within India, and RBI's requirement to store payment data in India.

📖 Swami Ramdev v. Facebook, Inc. (Delhi High Court, 23 October 2019)

Facts: Videos repeating material already restrained as defamatory were circulating on Facebook, Google, YouTube and Twitter. The platforms offered to block access from India only (geo-blocking).

Held: Content uploaded from India, or from a computer resource in India, must be removed or disabled globally, not merely blocked for Indian users; content uploaded from outside India must be geo-blocked for India. The Court relied on Section 79(3)(b), reading 'computer resource' to include the global network, and on Section 75.

Significance: The leading Indian ruling on the global reach of takedown orders. It was appealed to a Division Bench, and it remains debated on grounds of comity and free speech.

  • Banyan Tree Holding (P) Ltd. v. A. Murali Krishna Reddy (Delhi High Court, Division Bench, 2009). For civil jurisdiction based on a website, mere accessibility in the forum is not enough; the defendant must have purposefully targeted the forum, a test that limits over-broad online jurisdiction.

7. Illustrations

  • A hacker in Eastern Europe breaches an Indian bank's server. Covered by Sections 66 and 75: an Indian computer is involved, and nationality is irrelevant.
  • A foreign company abroad scrapes data from an Indian startup's server without permission. A contravention under Section 43 read with Section 75; the startup may claim compensation before the adjudicating officer, though recovery abroad is a practical problem.
  • An Indian student in London hacks a British university's server. No Indian computer is involved, so Section 75 does not apply. BNS offences, if any, may apply to him as a citizen under s.1(5)(a), subject to sanction under s.208 BNSS.
  • A person abroad sends threatening emails to an Indian user. The emails are received on a device in India, so the act involves a computer in India, and the Act may apply along with the BNS.

8. Assessment

  • Strength. A clear, simple nexus test that protects Indian systems from attacks launched abroad.
  • Weakness. Jurisdiction on paper is not enforcement in practice. Without extradition or cooperation, a judgment against a person abroad may be unenforceable.
  • Risk of overreach. Global takedown orders and broad readings of 'involves' can conflict with the laws of other countries and with international comity.

9. Quick Revision and Memory Aids

  • 'Stone across the border'. The effects principle behind Section 75.
  • 'Computer, not citizen'. The nexus is the Indian computer, not the offender's nationality.
  • '1(2) extends, 75 limits'. How the two provisions work together.
  • 'BNS 1(5)(c) targets computer resource'. The parallel hook in the penal code.
  • '208 needs sanction'. Central Government sanction for trying offences committed abroad.
  • 'Ramdev: uploaded here, removed everywhere'. Global takedown.

10. Frequently Asked Questions

Does the IT Act apply to a foreigner who commits a cyber offence from outside India?

Yes, under Sections 1(2) and 75, if the act or conduct involves a computer, computer system or computer network located in India, irrespective of the offender's nationality.

Does Section 75 apply to civil contraventions?

Yes. It covers any 'offence or contravention', so a person abroad may be liable to pay compensation under Chapter IX.

Is sanction required to try an offence committed outside India?

Under Section 208 BNSS, previous sanction of the Central Government is required to inquire into or try an offence committed outside India, but not for offences committed within India (Thota Venkateswarlu, 2011).

11. Related Topics

  • Topic 1: Introduction, Object and Scope. Territorial scope in outline.
  • Topic 11: IT Act as Special Legislation. How the Act relates to the BNS.